The Springfield Public Schools cyberattack that closed classrooms for a week has now produced the disclosure that matters legally: student and staff data was compromised. The FBI is investigating. Students returned Monday. What parents want to know is what was taken, and the district has not said.
Massachusetts law answers part of that question on a schedule, whether or not the investigation is finished. This piece explains what a public school district owes families after a breach, what the notice must contain and when it must arrive, what the free credit protections are worth for a child, and what a parent can do this week without waiting for a letter.
What is known
Springfield Public Schools canceled classes for a week after what the district described as a cyber incident in which an outside group gained access to its network and blocked access to certain third-party online programs, including student medical records, transportation and food services. Classes resumed Monday, September 14. On Monday and Tuesday, the district and the FBI confirmed that student and staff data was breached. The scope, the categories of data, and the number of people affected have not been stated publicly.
The same week, Everett City Hall remained closed after a separate cybersecurity incident, now in its second week, with no cause disclosed. We cover what Everett residents are owed in our guide to that closure. The two incidents are unrelated on the public record.
The Massachusetts breach law applies to school districts
G.L. c. 93H is the Commonwealth’s data breach statute, and it covers any person or agency that owns or licenses personal information about a Massachusetts resident. “Agency” includes a political subdivision of the Commonwealth, which is what a municipal school district is. There is no school exemption.
The statute is triggered by unauthorized acquisition or use of “personal information,” which it defines narrowly: a resident’s name combined with a Social Security number, a driver’s license or state ID number, or a financial account or credit or debit card number. A student’s name and address alone are not personal information under the statute. A student’s name plus Social Security number is.
That distinction is why districts often take weeks to say what was taken. Determining which category of record was accessed is the work that decides whether the notice obligation exists at all.
What the notice must say, and when
Notice is due “as soon as practicable and without unreasonable delay” after the district knows or has reason to know of a breach. There is no fixed day count in the statute, which is the provision’s weakness. Law enforcement can ask a district to delay notice while an investigation proceeds, and an FBI investigation is exactly that circumstance.
Three notices are required. To the Attorney General’s office. To the Office of Consumer Affairs and Business Regulation. And to each affected resident.
The two government notices and the notice to families are not the same document, and the difference explains a great deal of the frustration these letters cause. The notice to the Attorney General and the Office of Consumer Affairs must state the nature of the breach, the number of residents affected, the type of personal information compromised, who was responsible if known, and whether the district maintains a written information security program.
The notice to the resident must state four things: the right to obtain a police report, how to request a security freeze, that there is no charge for the freeze, and the mitigation services being offered. And then the statute says the resident’s notice “shall not include the nature of the breach of security or unauthorized acquisition or use, or the number of residents of the commonwealth affected.” Families are told less than regulators by design. A letter that seems uninformative is following the law, not evading it.
The statute also forbids delaying notice because the total number affected has not been determined, and requires a follow-up notice when more is learned.
Where Social Security numbers were disclosed or are reasonably believed to have been, G.L. c. 93H, § 3A requires the district to contract with a third party to offer each affected resident credit monitoring at no cost for at least 18 months, and forbids requiring anyone to waive their right to sue as a condition of receiving it.
Separately, student education records are governed by the federal Family Educational Rights and Privacy Act, which has no breach notification requirement of its own but does require districts to use reasonable methods to protect records and to maintain a record of disclosures. A FERPA violation is enforced by the federal Department of Education, not by a private lawsuit.
Why a child’s stolen data is different
A child has no credit history, which makes a child’s Social Security number more useful to an identity thief than an adult’s, not less. A file opened in a child’s name can go undetected for years, often until the child applies for a first loan, a first apartment or financial aid. The damage surfaces at the worst possible moment.
Massachusetts parents have a specific tool. A parent or guardian can place a security freeze on the credit file of a child under 16, and if no file exists, the credit reporting agency must create one and then freeze it. It is free. A frozen file cannot be used to open new credit, which is the entire mechanism of child identity theft. It has to be done separately at each of the three national agencies: Equifax, Experian and TransUnion.
This is worth doing without waiting for a district letter. The freeze costs nothing, does not affect anything else in the child’s life, and can be lifted later.
What parents can do this week
Place a protective freeze on each child’s credit file at all three agencies. Each has a minor freeze process that requires proof of identity and of the parent’s relationship, usually a birth certificate and the parent’s identification.
Watch for mail in a child’s name. Pre-approved credit offers, collection notices, or an Internal Revenue Service notice saying a return has already been filed using the child’s Social Security number are the common first signs.
Keep a copy of anything the district sends. A notice letter establishes the date the district says it learned of the breach, and that date matters if a claim is ever made.
Ask the district, in writing, which categories of data were involved and whether Social Security numbers were among them. A district’s answer, or its refusal, is a public record request away under the Massachusetts public records law, though records related to an active law enforcement investigation may be withheld.
Whether anyone can sue
Chapter 93H has no private right of action. A resident cannot sue under the statute itself; enforcement belongs to the Attorney General, who may seek civil penalties and whose office treats a violation as an unfair practice under G.L. c. 93A.
A claim against a school district faces a further obstacle. The Massachusetts Tort Claims Act, G.L. c. 258, requires written presentment to the executive officer of the public employer within two years and caps damages against a municipality at $100,000. It also preserves immunity for discretionary functions, and a district’s choices about cybersecurity spending are the kind of decision courts have treated as discretionary. Data breach claims generally founder earlier than that, on the requirement that a plaintiff show actual harm rather than an increased risk of future harm.
The realistic remedies here are the statutory ones: notice, free credit monitoring where Social Security numbers were exposed, and a free freeze.
Common questions
Does Massachusetts breach law cover public schools?
Yes. G.L. c. 93H applies to any agency, which includes political subdivisions of the Commonwealth. There is no school district exemption.
How long does a district have to notify families?
As soon as practicable and without unreasonable delay. There is no fixed deadline, and law enforcement may ask for a delay during an active investigation.
Why does a breach notice say so little?
Because the statute forbids it. The notice to a resident may not describe the nature of the breach or the number of residents affected, although the notice to the Attorney General must contain both.
Can I freeze my child’s credit?
Yes, for free. A parent or guardian may freeze the file of a child under 16, and the agency must create a file if none exists in order to freeze it. Do it at Equifax, Experian and TransUnion separately.
Can families sue the district?
Chapter 93H creates no private right of action. A tort claim against a district faces presentment requirements, a $100,000 cap under the Tort Claims Act, and the requirement to prove actual harm.
Springfield facts as reported by Boston 25 News, WCVB, WHDH and NBC10 Boston, September 15 and 16, 2026, and the Insurance Journal’s September 11 report on the reopening; the district has not publicly stated the scope of the breach. G.L. c. 93H, including §§ 1, 3 and 3A, and c. 258 read at malegislature.gov. Credit freeze procedures from the three national credit reporting agencies. General information about Massachusetts law, not legal advice.
